🟠 High  |  Source: Microsoft Security Response Center


A use-after-free vulnerability in WebGL (CVE-2026-13032) has been identified in the Chromium engine, which underpins Microsoft Edge. Use-after-free flaws can allow attackers to execute arbitrary code by manipulating freed memory, potentially compromising a user’s system simply by visiting a malicious webpage. Microsoft has addressed this in Edge by ingesting the upstream Chromium fix from Google.

Security Architect’s Take: Ensure Microsoft Edge is updated to the latest Chromium-based release across all managed endpoints and virtual desktop environments, including Azure Virtual Desktop. Prioritise patching for users with privileged cloud console access, as browser-based code execution could expose Azure portal sessions.

Original advisory: Chromium: CVE-2026-13032 Use after free in WebGL